MGASA-2020-0371

Source
https://advisories.mageia.org/MGASA-2020-0371.html
Import Source
https://advisories.mageia.org/MGASA-2020-0371.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0371
Related
Published
2020-09-27T20:06:37Z
Modified
2020-09-23T17:19:09Z
Summary
Updated kio-extras packages fix security vulnerability
Details

fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of the password (CVE-2020-12755).

References
Credits

Affected packages

Mageia:7 / kio-extras

Package

Name
kio-extras
Purl
pkg:rpm/mageia/kio-extras?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
19.04.0-1.1.mga7

Ecosystem specific

{
    "section": "core"
}